Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
squid squid vulnerabilities and exploits
(subscribe to this query)
5
CVSSv2
CVE-2016-10003
Incorrect HTTP Request header comparison in Squid HTTP Proxy 3.5.0.1 up to and including 3.5.22, and 4.0.1 up to and including 4.0.16 results in Collapsed Forwarding feature mistakenly identifying some private responses as being suitable for delivery to multiple clients.
Squid-cache Squid
5
CVSSv2
CVE-2016-2570
The Edge Side Includes (ESI) parser in Squid 3.x prior to 3.5.15 and 4.x prior to 4.0.7 does not check buffer limits during XML parsing, which allows remote HTTP servers to cause a denial of service (assertion failure and daemon exit) via a crafted XML document, related to esi/Cu...
Squid-cache Squid 3.2.0.18
Squid-cache Squid 3.1.0.18
Squid-cache Squid 3.0.stable13
Squid-cache Squid 3.3.3
Squid-cache Squid 3.2.0.9
Squid-cache Squid 3.3.11
Squid-cache Squid 3.0
Squid-cache Squid 4.0.5
Squid-cache Squid 3.0.stable9
Squid-cache Squid 3.1.13
Squid-cache Squid 4.0.3
Squid-cache Squid 3.3.5
Squid-cache Squid 3.2.0.1
Squid-cache Squid 3.0.stable20
Squid-cache Squid 3.3.0.3
Squid-cache Squid 3.0.stable14
Squid-cache Squid 3.3.13
Squid-cache Squid 3.2.2
Squid-cache Squid 3.0.stable3
Squid-cache Squid 3.2.4
Squid-cache Squid 3.2.0.6
Squid-cache Squid 3.1.0.7
5
CVSSv2
CVE-2016-2572
http.cc in Squid 4.x prior to 4.0.7 relies on the HTTP status code after a response-parsing failure, which allows remote HTTP servers to cause a denial of service (assertion failure and daemon exit) via a malformed response.
Squid-cache Squid 4.0.5
Squid-cache Squid 4.0.3
Squid-cache Squid 4.0.1
Squid-cache Squid 4.0.2
Squid-cache Squid 4.0.4
Squid-cache Squid 4.0.6
5
CVSSv2
CVE-2014-0128
Squid 3.1 prior to 3.3.12 and 3.4 prior to 3.4.4, when SSL-Bump is enabled, allows remote malicious users to cause a denial of service (assertion failure) via a crafted range request, related to state management.
Squid-cache Squid 3.2.0.18
Squid-cache Squid 3.1.0.18
Squid-cache Squid 3.3.3
Squid-cache Squid 3.2.0.9
Squid-cache Squid 3.3.11
Squid-cache Squid 3.1.13
Squid-cache Squid 3.3.5
Squid-cache Squid 3.2.0.1
Squid-cache Squid 3.3.0.3
Squid-cache Squid 3.2.2
Squid-cache Squid 3.2.4
Squid-cache Squid 3.2.0.6
Squid-cache Squid 3.1.0.7
Squid-cache Squid 3.1.0.14
Squid-cache Squid 3.2.0.15
Squid-cache Squid 3.1.0.12
Squid-cache Squid 3.1.1
Squid-cache Squid 3.1.0.3
Squid-cache Squid 3.1.0.1
Squid-cache Squid 3.4.2
Squid-cache Squid 3.2.10
Squid-cache Squid 3.4.3
5
CVSSv2
CVE-2013-4123
client_side_request.cc in Squid 3.2.x prior to 3.2.13 and 3.3.x prior to 3.3.8 allows remote malicious users to cause a denial of service via a crafted port number in a HTTP Host header.
Squid-cache Squid 3.3.3
Squid-cache Squid 3.3.5
Squid-cache Squid 3.3.0.3
Squid-cache Squid 3.3.7
Squid-cache Squid 3.3.2
Squid-cache Squid 3.3.1
Squid-cache Squid 3.3.0
Squid-cache Squid 3.3.0.2
Squid-cache Squid 3.3.4
Squid-cache Squid 3.3.6
Opensuse Opensuse 12.3
Squid-cache Squid 3.2.0.18
Squid-cache Squid 3.2.0.9
Squid-cache Squid 3.2.0.1
Squid-cache Squid 3.2.2
Squid-cache Squid 3.2.4
Squid-cache Squid 3.2.0.6
Squid-cache Squid 3.2.0.15
Squid-cache Squid 3.2.10
Squid-cache Squid 3.2.0.19
Squid-cache Squid 3.2.0.13
Squid-cache Squid 3.2.0.16
1 EDB exploit
5
CVSSv2
CVE-2013-0189
cachemgr.cgi in Squid 3.1.x and 3.2.x, possibly 3.1.22, 3.2.4, and other versions, allows remote malicious users to cause a denial of service (resource consumption) via a crafted request. NOTE: this issue is due to an incorrect fix for CVE-2012-5643, possibly involving an incorre...
Squid-cache Squid 3.1.0.18
Squid-cache Squid 3.1.13
Squid-cache Squid 3.1.0.7
Squid-cache Squid 3.1.0.14
Squid-cache Squid 3.1.0.12
Squid-cache Squid 3.1.1
Squid-cache Squid 3.1.0.3
Squid-cache Squid 3.1.0.1
Squid-cache Squid 3.1.22
Squid-cache Squid 3.1.14
Squid-cache Squid 3.1.8
Squid-cache Squid 3.1.6
Squid-cache Squid 3.1.0.9
Squid-cache Squid 3.1.0.15
Squid-cache Squid 3.1.15
Squid-cache Squid 3.1.0.13
Squid-cache Squid 3.1.12
Squid-cache Squid 3.1.10
Squid-cache Squid 3.1.3
Squid-cache Squid 3.1.0.2
Squid-cache Squid 3.1.5
Squid-cache Squid 3.1.7
5
CVSSv2
CVE-2012-5643
Multiple memory leaks in tools/cachemgr.cc in cachemgr.cgi in Squid 2.x and 3.x prior to 3.1.22, 3.2.x prior to 3.2.4, and 3.3.x prior to 3.3.0.2 allow remote malicious users to cause a denial of service (memory consumption) via (1) invalid Content-Length headers, (2) long POST r...
Squid-cache Squid 2.6
Squid-cache Squid 2.0
Squid-cache Squid 2.7
Squid-cache Squid 2.2
Squid-cache Squid 2.3
Squid-cache Squid 2.5
Squid-cache Squid 2.1
Squid-cache Squid 2.4
Squid-cache Squid 3.1.0.18
Squid-cache Squid 3.0.stable13
Squid-cache Squid 3.1.21
Squid-cache Squid 3.0
Squid-cache Squid 3.0.stable9
Squid-cache Squid 3.1.13
Squid-cache Squid 3.0.stable20
Squid-cache Squid 3.0.stable14
Squid-cache Squid 3.0.stable3
Squid-cache Squid 3.1.17
Squid-cache Squid 3.1.0.7
Squid-cache Squid 3.1.0.14
Squid-cache Squid 3.0.stable4
Squid-cache Squid 3.1.0.12
5
CVSSv2
CVE-2012-2213
Squid 3.1.9 allows remote malicious users to bypass the access configuration for the CONNECT method by providing an arbitrary allowed hostname in the Host HTTP header. NOTE: this issue might not be reproducible, because the researcher is unable to provide a squid.conf file for a ...
Squid-cache Squid 3.1.9
1 Github repository
5
CVSSv2
CVE-2011-4096
The idnsGrokReply function in Squid prior to 3.1.16 does not properly free memory, which allows remote malicious users to cause a denial of service (daemon abort) via a DNS reply containing a CNAME record that references another CNAME record that contains an empty A record.
Squid-cache Squid 3.1.0.18
Squid-cache Squid 3.0.stable13
Squid-cache Squid 3.0
Squid-cache Squid 3.0.stable9
Squid-cache Squid 3.1.13
Squid-cache Squid 3.0.stable20
Squid-cache Squid 3.0.stable14
Squid-cache Squid 3.0.stable3
Squid-cache Squid 3.1.0.7
Squid-cache Squid 3.1.0.14
Squid-cache Squid 3.0.stable4
Squid-cache Squid 3.1.0.12
Squid-cache Squid 3.1.1
Squid-cache Squid 3.0.stable24
Squid-cache Squid 3.1.0.3
Squid-cache Squid 3.1.0.1
Squid-cache Squid 3.0.stable16
Squid-cache Squid 3.1.14
Squid-cache Squid 3.1.8
Squid-cache Squid 3.0.stable11
Squid-cache Squid 3.0.stable18
Squid-cache Squid 3.0.stable1
5
CVSSv2
CVE-2010-2951
dns_internal.cc in Squid 3.1.6, when IPv6 DNS resolution is not enabled, accesses an invalid socket during an IPv4 TCP DNS query, which allows remote malicious users to cause a denial of service (assertion failure and daemon exit) via vectors that trigger an IPv4 DNS response wit...
Squid-cache Squid 3.1.6
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
TCP
CVE-2024-4577
CVE-2024-2695
CVE-2024-31870
injection
CVE-2024-3813
arbitrary code
CVE-2024-27801
CVE-2024-30120
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
2
3
4
5
6
7
8
9
10
NEXT »